|
| 1 | +# Copyright (C) 2010 Splunk Inc. All Rights Reserved. Version 4.0 |
| 2 | +import sys,splunk.Intersplunk |
| 3 | +import re |
| 4 | +import urllib |
| 5 | +import xml.sax |
| 6 | +import xml.sax.saxutils as saxutils |
| 7 | +from xml.sax.handler import ContentHandler |
| 8 | +from xml.sax.handler import EntityResolver |
| 9 | +from xml.sax.xmlreader import InputSource |
| 10 | +import StringIO |
| 11 | +import types |
| 12 | + |
| 13 | +class NullInputSource(InputSource): |
| 14 | + def getByteStream(self): |
| 15 | + return StringIO.StringIO("entity files not supported.") |
| 16 | + |
| 17 | +class NullEntityResolver(EntityResolver): |
| 18 | + def resolveEntity(self,publicId,systemId): |
| 19 | + return NullInputSource() |
| 20 | + |
| 21 | +class XmlHandler(ContentHandler): |
| 22 | + def __init__(self, flatten): |
| 23 | + self.flatten = flatten |
| 24 | + |
| 25 | + def reset(self): |
| 26 | + self.key_prefix = [] |
| 27 | + self.keys_seen = [] |
| 28 | + self.new_fields = {} |
| 29 | + |
| 30 | + def getNewFields(self): |
| 31 | + return self.new_fields |
| 32 | + |
| 33 | + def setValue( self, value, suffix='' ): |
| 34 | + dest_key = '_'.join(self.key_prefix) + suffix |
| 35 | + |
| 36 | + if( len( str(value).strip() ) > 0 ): |
| 37 | + #handle multiple values |
| 38 | + if dest_key in self.new_fields: |
| 39 | + self.new_fields['multi values'] = 'yep' |
| 40 | + #this is only the second value, so convert value to a list |
| 41 | + if type(self.new_fields[dest_key]) is not types.ListType: |
| 42 | + self.new_fields[dest_key] = [self.new_fields[dest_key]] |
| 43 | + #append the value to the list |
| 44 | + self.new_fields[dest_key].append(str(value)) |
| 45 | + else: |
| 46 | + #insert the simple value |
| 47 | + self.new_fields[dest_key] = str(value) |
| 48 | + |
| 49 | + def startElement(self, name, attrs): |
| 50 | + self.key_prefix.append(name) |
| 51 | + |
| 52 | + #if flatten is set, then create a new prefix if this prefix has already been used |
| 53 | + if flatten and '_'.join(self.key_prefix) in self.keys_seen: |
| 54 | + self.key_prefix.pop() |
| 55 | + count = 2 |
| 56 | + newName = name + '[' + str(count) + ']' |
| 57 | + while '_'.join(self.key_prefix) + '_' + newName in self.keys_seen: |
| 58 | + count += 1 |
| 59 | + newName = name + '[' + str(count) + ']' |
| 60 | + self.key_prefix.append(newName) |
| 61 | + |
| 62 | + self.keys_seen.append( '_'.join(self.key_prefix) ) |
| 63 | + |
| 64 | + if attrs.getLength() > 0: |
| 65 | + for k in attrs.getNames(): |
| 66 | + self.setValue( attrs.getValue(k), "-" + k ) |
| 67 | + |
| 68 | + def characters(self, content): |
| 69 | + if content is not None and content.strip() is not '': |
| 70 | + self.setValue( content.strip() ) |
| 71 | + |
| 72 | + def endElement(self, name): |
| 73 | + self.key_prefix.pop() |
| 74 | + |
| 75 | + |
| 76 | +try: |
| 77 | + results,dummyresults,settings = splunk.Intersplunk.getOrganizedResults() |
| 78 | + |
| 79 | + keywords, argvals = splunk.Intersplunk.getKeywordsAndOptions() |
| 80 | + |
| 81 | + flatten = argvals.get("flatten", "False") |
| 82 | + if flatten.strip().lower() in ['true','1','yes']: |
| 83 | + flatten = True |
| 84 | + else: |
| 85 | + flatten = False |
| 86 | + |
| 87 | + handler = XmlHandler(flatten) |
| 88 | + |
| 89 | + for r in results: |
| 90 | + try: |
| 91 | + if 'xml' in r: |
| 92 | + xml_text = r['xml'] |
| 93 | + else: |
| 94 | + raw = r["_raw"] |
| 95 | + |
| 96 | + xml_text = raw[ raw.index( '<' ) : raw.rindex( '>' )+1 ] |
| 97 | + |
| 98 | + handler.reset() |
| 99 | + |
| 100 | + parser = xml.sax.make_parser() |
| 101 | + parser.setContentHandler(handler) |
| 102 | + parser.setEntityResolver(NullEntityResolver()) |
| 103 | + parser.parse(StringIO.StringIO(xml_text)) |
| 104 | + |
| 105 | + for k,v in handler.getNewFields().iteritems(): |
| 106 | + r[k] = v |
| 107 | + except: |
| 108 | + import traceback |
| 109 | + stack = traceback.format_exc() |
| 110 | + r['_raw'] = "Failed to parse: " + str(stack) + "\n" + r['_raw'] |
| 111 | + |
| 112 | +except: |
| 113 | + import traceback |
| 114 | + stack = traceback.format_exc() |
| 115 | + results = splunk.Intersplunk.generateErrorResults("Error : Traceback: " + str(stack)) |
| 116 | + |
| 117 | +splunk.Intersplunk.outputResults( results ) |
0 commit comments